Advisories ยป MGASA-2014-0024

Updated nss packages fix security vulnerability

Publication date: 21 Jan 2014
Modification date: 21 Jan 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1740

Description

Updated nss packages fix security vulnerability:

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla
Network Security Services (NSS) before 3.15.4, when the TLS False
Start feature is enabled, allows man-in-the-middle attackers to spoof
SSL servers by using an arbitrary X.509 certificate during certain
handshake traffic (CVE-2013-1740).
                

References

SRPMS

3/core